Bekker's Blog

Blog archive

Which Unpatched Holes Most Appeal to Attackers?

There are few better ways to guarantee a system will be breached, compromised and exploited than failing to keep up with vendors' patches. Yet millions of public-facing systems run unpatched.

In an effort to document which previously reported security vulnerabilities are most popular with attackers, government public computer security awareness agencies from five countries on Wednesday released a Top 30 list of targeted high-risk vulnerabilities.

"This Alert provides information on the 30 most commonly exploited vulnerabilities used in these attacks, along with prevention and mitigation recommendations," read an alert from the U.S. Department of Homeland Security's National Cybersecurity and Communications Integration Center and the U.S. Computer Emergency Readiness Team.

An analysis by the Canadian Cyber Incident Response Centre provides the foundation for the list, which was jointly developed by government computer security organizations in Australia, Canada, New Zealand, the United Kingdom and the United States.

The vulnerabilities are not listed by severity. Instead, they are grouped by the vendor or project whose software is affected. Microsoft accounts for 16 of the vulnerabilities, Adobe for 11, Oracle for 2 and OpenSSL for 1.

What's both interesting and depressing about the list is how old some of the vulnerabilities are. For example, in the Microsoft list, some of the 30 most commonly exploited vulnerabilities date to 2009 and 2008, as well as an Internet Explorer malware issue, which first emerged almost nine years ago.

On Microsoft platforms, the attackers' favorite flaws come from the following bulletins:

  • MS08-042
  • MS09-067
  • MS09-072
  • MS10-018
  • MS10-087
  • MS11-021
  • MS12-027
  • MS12-060
  • MS13-008
  • MS13-022
  • MS13-038
  • MS14-012
  • MS14-017
  • MS14-021
  • MS14-060

The malware issue with Internet Explorer is CVE-2006-3227.

The U.S. version of the Top 30 bulletin is available here.

Posted by Scott Bekker on April 29, 2015 at 10:33 AM


Featured

  • 2019 Microsoft Conference Calendar: For Partners, IT Pros and Developers

    Here's your guide to all the IT training sessions, partner meet-ups and annual Microsoft conferences you won't want to miss this year.

  • Microsoft-Mover Deal Aimed at Boosting Microsoft 365 Adoption

    Microsoft has announced its acquisition of Mover, maker of a platform that assists medium-to-large companies in moving their files to cloud-based services.

  • Azure AD Outage Linked to Multifactor Authentication Issues

    An Azure Active Directory outage that lasted for about 2.5 hours was caused by multifactor authentication challenges not working, according to Microsoft.

  • The 2019 Microsoft Product Roadmap

    From the next major update to Windows 10 to the next generation of HoloLens, here's what's on tap from Microsoft this year.

RCP Update

Sign up for our newsletter.

Terms and Privacy Policy consent

I agree to this site's Privacy Policy.